variable-misuse

1 article
sort: new top best
clear filter
0 7/10
bug-bounty

A logic error in Synthetix's fee reclamation feature allowed attackers to receive inflated amounts when exchanging synths because the _exchange function used the wrong variable (sourceAmount instead of sourceAmountAfterSettlement) when calculating rebates, resulting in a $150,000 payout to the whitehat researcher.

Synthetix thunderdeep14 Immunefi Nexus Mutual SIP 236
medium.com · unknown · 23 hours ago · details